Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zimbra Flaw Exploited for Web Shell Deployment

Zimbra Flaw Exploited for Web Shell Deployment

Posted on September 30, 2026 By CWS

Recent findings by the Microsoft Security Research team reveal that threat actors have exploited a now-patched vulnerability in the Zimbra Collaboration Suite (ZCS) to deploy web shells and access sensitive mailbox data. This exploitation targets the CVE-2026-73570 vulnerability, a critical unauthenticated operating system command injection flaw with a CVSS score of 8.9 that allows remote code execution when SNMP notifications are enabled and the optional zimbra-snmp package is installed.

Details of the Security Breach

The exploitation of CVE-2026-73570 can be initiated via a specially crafted SMTP request, affecting exposed Zimbra servers without requiring authentication. Zimbra addressed this vulnerability in July 2026 with the release of version 10.1.20. According to Microsoft, successful exploitation has led to the deployment of JSP web shells and reverse shells, privilege escalation, and the use of persistent remote-access tools, with threat actors accessing email and harvesting authentication information.

Global Impact and Discovery

Microsoft observed this attack affecting organizations across multiple regions and industries. Although not all affected hosts exhibited every stage of the attack, the precise identity of the threat actors remains unknown. Initial reports of the active exploitation came from the Polish Computer Emergency Response Team (CERT Polska) in August 2026, which urged users to check for suspicious activity, such as service restarts and file creations in specific directories.

Furthermore, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply necessary patches by August 24, 2026. Microsoft documented attack activities occurring between July 20 and August 13, 2026, with initial reconnaissance using out-of-band scanning tools.

Attack Techniques and Mitigation

Attackers utilized the initial access to execute commands as the “zimbra” service account, deploying multiple JSP web shells and downloading malicious payloads. They maintained persistence through cron jobs, systemd services, and memory-backed execution techniques. In some instances, attackers briefly enabled write access to public directories to deploy web shells, minimizing detection by reverting permissions afterward.

To mitigate these threats, organizations are strongly advised to apply the latest security updates. If patching is not feasible, it’s recommended to remove the zimbra-snmp package, disable SNMP notifications, and limit SNMP and SMTP access to trusted hosts. Additional measures include rotating authentication secrets and scanning for redundant web shell persistence.

Conclusion and Security Recommendations

The exploitation of the Zimbra flaw underscores the importance of timely vulnerability patching and proactive security measures. Organizations must remain vigilant and implement recommended safeguards to prevent unauthorized access and data breaches. By staying informed and responsive, businesses can protect their systems against evolving cybersecurity threats.

The Hacker News Tags:authentication breach, CERT Polska, CISA, CVE-2026-73570, cyber attack, cybersecurity threat, mailbox data, Microsoft security, network security, remote code execution, SNMP, vulnerability patching, web shell, Zimbra security

Post navigation

Previous Post: Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics
Next Post: Cloudflare Advances Quantum-Safe Internet Security

Related Posts

BKA Unveils Key Figures in REvil Ransomware Operations BKA Unveils Key Figures in REvil Ransomware Operations The Hacker News
Google Enhances Android Privacy and Blocks 8.3B Ads Google Enhances Android Privacy and Blocks 8.3B Ads The Hacker News
Docker Fixes CVE-2025-9074, Critical Container Escape Vulnerability With CVSS Score 9.3 Docker Fixes CVE-2025-9074, Critical Container Escape Vulnerability With CVSS Score 9.3 The Hacker News
Zimbra Releases Fixes for Critical SNMP and XSS Flaws Zimbra Releases Fixes for Critical SNMP and XSS Flaws The Hacker News
SprySOCKS Backdoor Expands to Windows with New Variants SprySOCKS Backdoor Expands to Windows with New Variants The Hacker News
Hackers Breach Toptal GitHub, Publish 10 Malicious npm Packages With 5,000 Downloads Hackers Breach Toptal GitHub, Publish 10 Malicious npm Packages With 5,000 Downloads The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cloudflare Advances Quantum-Safe Internet Security
  • Zimbra Flaw Exploited for Web Shell Deployment
  • Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics
  • Hackers Exploit ChatGPT with ClickFix to Spread RAT
  • SectopRAT Variant Concealed in Windows Software Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cloudflare Advances Quantum-Safe Internet Security
  • Zimbra Flaw Exploited for Web Shell Deployment
  • Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics
  • Hackers Exploit ChatGPT with ClickFix to Spread RAT
  • SectopRAT Variant Concealed in Windows Software Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark